component-naming-sync

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from Figma design files, such as layer names and user comments. An attacker with access to the design file could embed instructions to manipulate the agent's behavior. \n
  • Ingestion points: Reads frames, components, instances, variables, styles, layers, prototype settings, comments, sections, and annotations from the active Figma context. \n
  • Boundary markers: The skill does not define specific delimiters or instructions to treat ingested content as untrusted data. \n
  • Capability inventory: The agent is authorized to perform scoped edits to Figma layer names and properties. \n
  • Sanitization: No sanitization or validation of the design-file content is performed before the agent uses it for naming synchronization tasks. \n
  • [NO_CODE]: The skill contains only instructional markdown in SKILL.md and does not include any executable scripts, binaries, or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:31 AM
Security Audit — agent-trust-hub — component-naming-sync